Compliance Program Charter - Texas
COMPLIANCE PROGRAM CHARTER — TEXAS SUPPLEMENT
Company: [________________________________]
Effective Date: [__/__/____]
Approved by: [________________________________]
Version: [____]
TABLE OF CONTENTS
- Purpose and Authorization
- Texas Regulatory Landscape
- Scope — Texas Compliance Domains
- Governance Enhancements
- Core Program Elements — Texas Focus
- Texas Regulatory Change Management
- Texas-Specific Reporting and Metrics
- Resources
- Review and Approval
- Annexes
1. PURPOSE AND AUTHORIZATION
This supplement addresses Texas-specific regulatory requirements including the TDPSA (effective July 1, 2024), the Texas breach notification statute, CUBI (biometric identifiers), the DTPA, and the TCHRA.
2. TEXAS REGULATORY LANDSCAPE
| Domain | Key Texas Statutes | Regulator |
|---|---|---|
| Privacy & Data Security | TDPSA (Ch. 541); Breach notification (§ 521.053); CUBI (§ 503.001) | TX AG |
| Consumer Protection | DTPA (Ch. 17); Tex. Bus. & Com. Code | TX AG; private plaintiffs |
| Employment | TCHRA (Lab. Code Ch. 21); Texas Payday Law (Lab. Code Ch. 61); Workers' Comp (Lab. Code Title 5) | TX Workforce Commission |
| Financial Services | TX Finance Code; TX Dept. of Banking; TX Dept. of Insurance | TX Banking Dept.; TDI |
| Energy/Environmental | TX Commission on Environmental Quality (TCEQ); Railroad Commission | TCEQ; RRC |
3. SCOPE — TEXAS COMPLIANCE DOMAINS
3.1 Privacy and Data Security
☐ TDPSA compliance: consumer rights (access, correction, deletion, portability, opt-out of targeted advertising, sale, profiling); processor obligations; data protection assessments; universal opt-out recognition; sensitive data consent
☐ Breach notification (§ 521.053): individual notice without unreasonable delay and no later than 60 days after determination; electronic AG notice as soon as practicable and no later than 30 days if at least 250 Texas residents are involved (S.B. 768, 2023)
☐ CUBI (§ 503.001): informed consent for biometric identifiers; no sale/disclosure; destruction within 1 year of purpose cessation
3.2 Consumer Protection
☐ DTPA (Ch. 17): prohibition of deceptive trade practices; laundry list of prohibited acts (§ 17.46(b)); treble damages for knowing violations
☐ Marketing, advertising, and sales practice review
3.3 Employment
☐ TCHRA (Lab. Code Ch. 21): discrimination and harassment protections (employers with 15+ employees)
☐ Texas Payday Law (Lab. Code Ch. 61): wage payment requirements
☐ At-will employment considerations
3.4 Biometric Data
☐ CUBI compliance program for any operations involving biometric identifiers
☐ Consent management and destruction tracking
4. GOVERNANCE ENHANCEMENTS
| Role | Texas Responsibilities |
|---|---|
| CCO | Oversee TX regulatory compliance; TX AG relationship management |
| Privacy Lead | TDPSA compliance; breach notification; CUBI compliance |
| Consumer Protection Counsel | DTPA review; marketing/sales compliance |
| Employment Counsel | TCHRA compliance; wage/hour |
| Board/Committee | Receive TX-specific compliance reports |
5. CORE PROGRAM ELEMENTS — TEXAS FOCUS
5.1 Risk Assessment — TX Additions
| Risk Area | Focus | Frequency |
|---|---|---|
| TDPSA compliance | Consumer rights, processor agreements, DPAs, opt-outs | Annual |
| CUBI compliance | Biometric data inventory, consent, destruction schedules | Annual |
| DTPA exposure | Marketing claims, disclosures, sales practices | Annual |
| TCHRA employment | Discrimination prevention, complaint handling | Annual |
| Breach readiness | 60-day notification; AG notification process | Annual |
5.2 Policies — TX-Specific
☐ TDPSA privacy notice and consumer rights procedures
☐ Texas breach notification procedures (individual notice without unreasonable delay/60-day ceiling; AG electronic notice at 250+ Texas residents/30-day ceiling)
☐ CUBI biometric data policy (consent, retention, destruction)
☐ DTPA marketing/advertising review procedures
☐ TCHRA anti-discrimination/anti-harassment policy
5.3 Training — TX-Specific
| Training | Audience | Frequency |
|---|---|---|
| TDPSA privacy awareness | Privacy team, customer service | Annual |
| CUBI biometric data handling | Employees handling biometric data | Annual |
| DTPA consumer protection | Marketing, sales | Annual |
| TCHRA discrimination prevention | All TX employees | Annual |
| Breach notification procedures | Incident response team | Annual |
5.4 Monitoring and Testing — TX Additions
☐ TDPSA consumer rights request handling verification
☐ Universal opt-out mechanism testing
☐ CUBI consent tracking and biometric destruction audit
☐ DTPA marketing review
☐ Breach notification tabletop (60-day timeline)
☐ TCHRA complaint tracking
5.5 Third-Party Risk — TX Additions
☐ TDPSA processor agreements for all TX data vendors (§ 541.104(b))
☐ CUBI vendor compliance for biometric data processing
☐ Vendor breach notification SLA alignment with 60-day timeline
☐ Data protection assessment cooperation requirements
6. TEXAS REGULATORY CHANGE MANAGEMENT
| Source | Monitoring |
|---|---|
| TX Legislature | Track proposed legislation (biennial sessions) |
| TX AG | Monitor enforcement actions and AG opinions |
| TX Workforce Commission | Monitor employment regulatory updates |
| Courts | Track significant TX privacy, consumer, employment decisions |
7. TEXAS-SPECIFIC REPORTING AND METRICS
| Metric | Target | Frequency |
|---|---|---|
| TDPSA consumer rights compliance | Within 45-day statutory deadline | Quarterly |
| Universal opt-out mechanism compliance | Verified | Annual |
| CUBI consent documentation | 100% coverage | Annual |
| CUBI destruction compliance | Within 1 year of purpose cessation | Annual |
| DTPA marketing review | All material campaigns | Ongoing |
| Breach notification readiness | Tabletop completed | Annual |
| TCHRA training completion | 100% of TX employees | Annual |
| Vendor TDPSA processor agreements | 100% applicable vendors | Quarterly |
8. RESOURCES
☐ Privacy team for TDPSA/CUBI
☐ Consumer protection review for DTPA
☐ Employment counsel for TCHRA
☐ External TX regulatory counsel
9. REVIEW AND APPROVAL
Review annually or upon material Texas regulatory change.
10. ANNEXES
Annex A: TX Breach Notification Checklist
☐ Breach determination (date: [__/__/____])
☐ 60-day notification clock starts (§ 521.053)
☐ Affected TX residents identified
☐ Individual notification prepared and sent
☐ If at least 250 Texas residents: TX AG notified electronically as soon as practicable and no later than 30 days after determination (S.B. 768, 2023)
☐ Records retained for AG inspection
Annex B: CUBI Compliance Checklist
☐ Biometric identifier inventory maintained (types: retina/iris scan, fingerprint, voiceprint, hand/face geometry)
☐ Informed consent obtained before capture (§ 503.001(b))
☐ Purpose and duration communicated to individuals before collection
☐ No sale, lease, or disclosure without consent (§ 503.001(c)(1))
☐ Stored with reasonable care, at least same standard as other confidential information (§ 503.001(c)(2))
☐ Destruction within 1 year of purpose cessation (§ 503.001(c)(3))
☐ Retention/destruction schedule documented and maintained
☐ Vendor CUBI compliance verified for biometric data processors
☐ Consent forms retained for audit purposes
Annex C: TDPSA Consumer Rights Compliance Checklist
☐ Privacy notice updated with TDPSA-required disclosures
☐ Consumer rights request intake mechanism operational
☐ Processes verified for all TDPSA rights:
- Right to confirm processing and access personal data (§ 541.051(b)(1))
- Right to correct inaccurate personal data (§ 541.051(b)(2))
- Right to delete personal data (§ 541.051(b)(3))
- Right to obtain copy in portable format (§ 541.051(b)(4))
- Right to opt out of targeted advertising (§ 541.051(b)(5)(A))
- Right to opt out of sale of personal data (§ 541.051(b)(5)(B))
-
Right to opt out of profiling for legal/significant decisions (§ 541.051(b)(5)(C))
☐ Response timeline: 45 days (one conditional 45-day extension with timely notice under § 541.052(b))
☐ Universal opt-out mechanism recognized (§ 541.055(e))
☐ Sensitive data consent mechanisms in place (§ 541.101(b)(4)): -
Racial/ethnic origin
- Religious beliefs
- Mental/physical health diagnosis
- Sexual orientation
- Citizenship/immigration status
- Genetic data
- Biometric data for identification
- Children's data (under 13)
- Precise geolocation
☐ COPPA compliance for known-child sensitive data (§ 541.101(b)(4))
☐ Data protection assessments completed for the processing listed in § 541.105(a), with the analysis required by subsection (b)
☐ Processor agreements include TDPSA-required terms (§ 541.104(b))
Annex D: Texas Regulatory Calendar
| Date/Period | Event | Responsible |
|---|---|---|
| Ongoing | TDPSA consumer rights requests (45-day response) | Privacy |
| Ongoing | Breach notification (60-day deadline from determination) | Security / Compliance |
| Annual | CUBI biometric inventory and destruction audit | Compliance |
| Annual | TDPSA data protection assessment updates | Privacy |
| Annual | DTPA marketing review | Consumer Protection Counsel |
| Annual | TCHRA training completion | HR / Employment Counsel |
| Annual | Breach notification tabletop exercise | Security |
| Biennial | TX Legislative session monitoring | Compliance / Legal |
Annex E: DTPA Compliance Checklist
☐ Marketing materials reviewed for deceptive trade practices
☐ Product/service representations verified for accuracy
☐ Pricing disclosures complete and not misleading
☐ Warranty and guarantee terms clearly stated
☐ Advertising claims substantiated with documentation
☐ Laundry list violations reviewed (§ 17.46(b)) — including:
- False representations of goods/services
- Failure to disclose material information
- Bait-and-switch practices
- Unconscionable actions
☐ Customer complaint tracking operational for DTPA-related issues
SOURCES AND REFERENCES
- TDPSA, Tex. Bus. & Com. Code Ch. 541 (eff. July 1, 2024)
- Tex. Bus. & Com. Code § 521.053 (Breach Notification; 60 Days)
- Tex. Bus. & Com. Code § 503.001 (CUBI)
- DTPA, Tex. Bus. & Com. Code Ch. 17
- TCHRA, Tex. Lab. Code Ch. 21
- HB 4 (88th Legislature, 2023) — AG enforcement enhancements
- DOJ Evaluation of Corporate Compliance Programs (Updated September 2024)
- U.S. Sentencing Guidelines § 8B2.1
This template is provided for informational purposes only and does not constitute legal advice. Consult qualified legal counsel before use.
About this template
- Last updated
- September 19, 2026
- Jurisdiction
- Texas
- Category
- Compliance & Regulatory
Legal authority
- U.S. Sentencing Guidelines § 8B2.1
- DOJ Evaluation of Corporate Compliance Programs (Updated September 2024)
- Texas Data Privacy and Security Act (TDPSA), Tex. Bus. & Com. Code Ch. 541
- Tex. Bus. & Com. Code § 521.053 (Breach Notification)
- Tex. Bus. & Com. Code § 503.001 (CUBI)
- Texas Deceptive Trade Practices Act (DTPA), Tex. Bus. & Com. Code Ch. 17
- Texas Commission on Human Rights Act (TCHRA), Tex. Lab. Code Ch. 21
- SOX § 301, § 806
Compliance documents are what regulated businesses use to prove they follow the rules that apply to their industry, whether that is privacy, anti-money-laundering, consumer protection, or sector-specific requirements. Regulators look for consistent policies, up-to-date records, and clear evidence of employee training. The cost of getting compliance paperwork right is almost always smaller than the cost of an enforcement action, fine, or public disclosure.
Not legal advice
This template is provided for informational purposes. We recommend having an attorney review any legal document before signing, especially for high-value or complex matters.
Checked against the law it cites
The statutes this template relies on are listed under Legal authority.
Tex. Bus. & Com. Code §§ 541.104-.105 (checked September 19, 2026): "A contract between a controller and a processor shall govern the processor's data processing procedures with respect to processing performed on behalf of the controller. A controller shall conduct and document a data protection assessment of each of the following processing activities involving personal data."
Tex. Bus. & Com. Code § 521.053(b)-(c) (checked September 12, 2026): "A person who conducts business in this state and owns or licenses computerized data that includes sensitive personal information shall disclose any breach of system security, after discovering or receiving notification of the breach, to any individual whose sensitive personal information was, or is reasonably believed to have been, acquired by an unauthorized person. The disclosure shall be made without unreasonable delay and in each case not later than the 60th day after the date on which the person determines that the breach occurred, except as provided by Subsection (d) or as necessary to determine the scope of the breach and restore the reasonable integrity of the data system. Any person who maintains computerized data that includes sensitive personal information not owned by the person shall notify the owner or license holder of the information of any breach of system security immediately after discovering the breach, if the sensitive personal information was, or is reasonably believed to have been, acquired by an unauthorized person."
Tex. Bus. & Com. Code § 521.053(h)-(i) (checked September 12, 2026): "If a person is required by this section to notify at one time more than 10,000 persons of a breach of system security, the person shall also notify each consumer reporting agency, as defined by 15 U.S.C. Section 1681a, that maintains files on consumers on a nationwide basis, of the timing, distribution, and content of the notices. A person who is required to disclose or provide notification of a breach of system security under this section shall notify the attorney general of that breach as soon as practicable and not later than the 30th day after the date on which the person determines that the breach occurred if the breach involves at least 250 residents of this state."
DOJ Evaluation of Corporate Compliance Programs (Updated September 2024) (checked September 5, 2026): "This document is meant to assist prosecutors in making informed decisions as to whether, and to what extent, the corporation’s compliance program was effective at the time of the offense, and is effective at the time of a charging decision or resolution, for purposes of determining the appropriate (1) form of any resolution or prosecution; (2) monetary penalty, if any; and (3) compliance obligations contained in any corporate criminal resolution (e.g., monitorship or reporting obligations)."
Draft your Compliance Program Charter - Texas in the editor
Answer a few questions, let the AI editor draft each section from your answers, review it, and download Word and PDF. $99 one time, or $249 per month for every document and every Ezel app.